Skip to content

Commit c0a8aee

Browse files
committed
security fix: CP-10: Admin Websites Suspend / Unsuspend
1 parent bc67e56 commit c0a8aee

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

websiteFunctions/website.py

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -574,6 +574,12 @@ def submitWebsiteStatus(self, userID=None, data=None):
574574

575575
website = Websites.objects.get(domain=websiteName)
576576

577+
admin = Administrator.objects.get(pk=userID)
578+
if ACLManager.checkOwnership(websiteName, admin, currentACL) == 1:
579+
pass
580+
else:
581+
return ACLManager.loadErrorJson('websiteStatus', 0)
582+
577583
if state == "Suspend":
578584
confPath = virtualHostUtilities.Server_root + "/conf/vhosts/" + websiteName
579585
command = "mv " + confPath + " " + confPath + "-suspended"

0 commit comments

Comments
 (0)